Where the code comes from¶
inbuxa started as a fork of Stalwart, and its server and console descend from it. Since then it has gone its own way. This page is the record of what was taken, what was left out, and how the rest was written. Everything on it can be checked against the public repositories it links to.
Each piece, and what it started from¶
| Piece | Started from | License |
|---|---|---|
| inbuxa server | The Stalwart mail server, v0.16.22, taken under the AGPL | AGPL-3.0-only |
| inbuxa Admin | Stalwart's web interface, v1.0.11, taken under the AGPL | AGPL-3.0-only |
| inbuxa Webmail | ihasmail, a Coffey Labs project | AGPL-3.0-or-later |
| inbuxa installer | ihasmail-oneshot, a Coffey Labs project | AGPL-3.0-or-later |
Upstream's copyright notices stay on every file they cover. Every file in the server and the console that was changed for inbuxa carries a notice saying so, and both repositories' checks fail a change that leaves one out.
What is taken, and what is left out¶
Stalwart publishes its code under two licenses: the AGPL, and a commercial
license for some files and parts of files, which it marks
LicenseRef-SEL. inbuxa takes the AGPL code only.
- Snapshots, not history. Each import is a snapshot of one tagged release. Upstream's git history is never brought in.
- Stripped before it is committed. A script removes every file and passage marked for the commercial license only, then checks that no marker is left. It reads the markers, not the code between them.
- A report for every import. What was removed, file by file, is committed beside the code: v0.16.22, v0.16.23 and v0.16.24. The first removed 63 files outright, and 117 marked passages from 50 others.
Features rebuilt clean-room¶
Nine features weren't in the AGPL code, so they were written again from nothing, under rules set down before any of them was started (SPEC.md §3):
- Specs come first, from public sources only: public documentation, the RFCs, the published schema (taken under the AGPL) and the observed behavior of a running server.
- Code comes from the specs only. Whoever implements a feature works from its written spec, and must never have seen the commercially licensed code.
- Every spec is dated, committed before its code, and names its sources. Where a source doesn't settle a behavior, the spec records a decision of its own rather than filling the gap from memory.
| Feature | Spec, with its sources | Spec committed | Built |
|---|---|---|---|
| Tenants | multi-tenancy.md | 18 Sep 2026 | 18 Sep 2026 |
| Masked addresses | masked-email.md | 18 Sep 2026 | 18 Sep 2026 |
| Undelete | undelete.md | 18 Sep 2026 | 18 Sep 2026 |
| Branding and templates | branding-and-templates.md | 18 Sep 2026 | 18 Sep 2026 |
| The language model's opinion on spam | ai-spam-classification.md | 18 Sep 2026 | 19 Sep 2026 |
| Monitoring history, live tracing and alerts | monitoring.md | 18 Sep 2026 | 19 Sep 2026 |
| SCIM provisioning | scim.md | 18 Sep 2026 | 19 Sep 2026 |
| Scale-out storage | scale-out-storage.md | 18 Sep 2026 | 19 Sep 2026 |
| A directory per domain | per-domain-directories.md | 18 Sep 2026 | 19 Sep 2026 |
License keys and seat limits weren't rebuilt. They were removed.
Features that are our own¶
Much of what inbuxa does now has no upstream counterpart, and was designed here from the start: the audit log, legal holds and locked accounts, data loss prevention and mail flow rules, journaling, the personal-data inventory and compliance officer roles, shared mailboxes, and the security to-do list. Specs for several, such as data loss prevention and journaling, are in the same folder. inbuxa Webmail and the installer were never derived from Stalwart's code.
How it is checked¶
- Scans of the whole history. On 18 and 19 September 2026, every commit of every branch of the server, the console and the webmail was searched for a file licensed only under the commercial license, and for any marked passage. None was found.
- Each later import goes through the same strip and gets its own report.
Security fixes¶
inbuxa keeps tracking Stalwart's security advisories for as long as its code stays close enough for a fix to apply.
Stalwart is a trademark of Stalwart Labs LLC. inbuxa is not affiliated with or endorsed by Stalwart Labs.